The rapid integration of artificial intelligence (AI) into business operations has outpaced the development and enforcement of robust governance frameworks, leading a significant portion of organizations to bypass established policies for urgent AI deployments. A recent survey by EY reveals that nearly half of companies (47%) have circumvented AI governance protocols to facilitate quick implementation, despite the vast majority (98%) having formal AI policies in place. This trend underscores a critical disconnect between technological advancement and the established structures designed to manage its risks.

The EY survey, which polled 202 senior AI decision-makers at US-based companies with revenues exceeding $1 billion, highlights a broader challenge: existing AI governance frameworks are struggling to keep pace with the evolving capabilities of AI technologies, particularly agentic AI. Agentic AI refers to AI systems that can autonomously plan and execute tasks, often exhibiting a degree of independent decision-making. The survey found that approximately half (49%) of respondents from organizations utilizing agentic AI indicated that their current governance structures have not been updated to encompass these advanced tools. Furthermore, a concerning 39% of these companies reported undefined accountability for the ongoing maintenance and monitoring of machine agents post-deployment. This lack of clarity creates fertile ground for unforeseen risks and potential ethical dilemmas.

Despite these governance gaps, the surveyed organizations are not entirely neglecting AI oversight. The EY report indicates a proactive approach to assurance, with nearly all (98%) companies conducting annual AI assurance reviews. These reviews appear to be instrumental in identifying and addressing issues, as a quarter of companies have completely halted certain AI applications following such assessments. An additional 64% have made significant modifications to their AI systems after these reviews, demonstrating a willingness to course-correct when problems are identified. The most prevalent issues flagged during these assurance reviews were related to data quality (57%), AI model drift – the degradation of AI performance over time due to changes in the input data – (48%), and shadow AI, which refers to AI solutions deployed and used without explicit IT department approval or oversight (39%).

The implications of this governance lag are far-reaching. As organizations increasingly rely on AI for critical functions, the potential for biased outputs, security vulnerabilities, and operational failures escalates. The bypass of established protocols, even for urgent deployments, suggests a prioritization of speed over comprehensive risk assessment, a trade-off that could have significant long-term repercussions. The undefined accountability for agentic AI, in particular, poses a substantial challenge for regulatory compliance and ethical AI development, as it leaves a critical gap in understanding who is responsible when these autonomous systems err.

Audit Leaders Grapple with Evolving Risk Landscape

The challenges in AI governance are mirrored by a broader difficulty faced by audit leaders in anticipating and mitigating emerging risks. A survey conducted by Gartner indicates that nearly two-thirds of audit leaders (64%) are finding it increasingly challenging to identify risks before they cause material harm. This sentiment suggests a widening gap between the speed at which risks are materializing and the capacity of traditional risk management and internal control systems to detect them proactively.

The Gartner survey, which involved 108 audit leaders, points to several factors contributing to this heightened risk prediction difficulty. The rapid adoption of AI, coupled with a volatile regulatory environment and persistent geopolitical uncertainties, is creating a complex and dynamic risk landscape that is overwhelming existing governance, control, and enterprise risk management (ERM) practices. This environment demands a more agile and sophisticated approach to risk identification and management.

Compounding this issue is a disconnect between audit insights and business action. While audit leaders are struggling to see risks coming, business leaders appear to be facing challenges in translating these critical insights into tangible actions. Only 30% of business leaders reported that their risk management efforts are significantly influenced by insights from audit, compliance, and ERM functions. This indicates a potential communication breakdown or a lack of integration between risk assurance providers and operational decision-makers.

Tegan Gebert, vice president in Gartner’s assurance practice, articulated the increased demands on business leaders: "This environment has raised the bar on what is required of business leaders. What it takes for them to fulfil their risk responsibilities is not only harder to achieve, but also even more critical to get right." This statement underscores the heightened stakes for leadership in navigating the current complex risk terrain. The inability of businesses to effectively leverage risk intelligence suggests a vulnerability to disruptions, financial losses, and reputational damage.

The implications for organizations are clear: without a more synchronized approach to risk identification and response, businesses are likely to remain reactive rather than proactive. This can lead to a continuous cycle of damage control, hindering strategic growth and eroding stakeholder confidence. The confluence of AI’s disruptive potential and the increasing difficulty in predicting broader risks creates a challenging environment for maintaining operational stability and achieving long-term objectives.

US Businesses Lag in AI Return on Investment Compared to Global Peers

While the allure of AI continues to drive investment globally, US businesses are experiencing a comparatively lower return on their AI investments than their counterparts in Europe and the Asia-Pacific region. A survey by IDC and Expereo found that only 15% of US companies reported that their AI return on investment (ROI) exceeded expectations, a figure significantly lower than the 40% reported by companies in the Asia-Pacific region. Globally, a more moderate 38% of organizations indicated that AI only partially met ROI expectations, while 37% stated that the technology broadly met their return expectations.

This divergence in AI ROI could be attributed to a variety of factors, including differing strategic approaches to AI implementation, varying levels of digital maturity, or distinct market dynamics. The survey of 800 multinational enterprises with 500 or more employees also revealed regional differences in scaling AI initiatives. European companies were most likely to scale back their AI efforts, with 22% reporting a reduction in AI deployment following unmet expectations. In contrast, the US saw a 10% rate of scaling back, and Asia-Pacific reported a mere 6%. This suggests that while US companies might be experiencing lower ROI, they are less inclined to retreat from AI investments compared to European counterparts.

The perceived widespread adoption of AI may also be less pronounced than often assumed. The IDC and Expereo survey indicated that a significant majority of organizations (62%) describe their current AI usage as "limited." Only 30% of companies consider their AI implementation to be "extensive" or "transformative." This suggests that while many organizations are experimenting with AI, few have achieved truly widespread or transformative integration.

A key motivator for AI investment across the globe is the fear of falling behind competitors. However, the intensity of this fear varies considerably by region. In the US, only 10% of leaders cited the fear of lagging behind as a primary driver for AI investment. This contrasts sharply with the Asia-Pacific region, where a substantial 37% of leaders are adopting AI out of concern for losing their competitive edge. This regional disparity in motivation could influence the strategic focus and perceived urgency of AI adoption, potentially impacting long-term success and ROI.

The implications of these findings suggest that US businesses may need to re-evaluate their AI strategies to better align with market expectations and ensure a more favorable ROI. The lower reported returns, coupled with a less pronounced fear of being left behind, could indicate a more cautious or less aggressive approach to AI integration, which may require recalibration to capture the full potential of the technology.

Critical AI Training Gaps Exposed Across Workforce

A substantial segment of the global workforce perceives a significant deficiency in their organizations’ AI training programs, particularly concerning the safe and secure utilization of AI technologies. A survey by TrustedTech, encompassing 2,001 employees across the US and UK, revealed that 44% of workers believe their organizations lack adequate training on using AI safely and securely. This concern is even more pronounced among company leaders, with 53% expressing the same sentiment regarding AI training.

The findings highlight a critical gap in knowledge transfer and skill development within organizations, especially concerning the responsible deployment and use of AI. This deficiency is further underscored by the fact that the primary source of AI education for both employees and decision-makers is not formal organizational training. Nearly a third of decision-makers (30%) reported being self-taught in AI, a figure even higher among general workers, with 41% indicating they learned on their own. Online resources like YouTube and blogs serve as significant learning platforms, with nearly a quarter of decision-makers (24%) and approximately 14% of workers acquiring their AI skills from these self-accessed sources. Formal employer training, while present, appears to be less prevalent, with 32% of leaders and about 15% of workers citing it as their source of AI skills.

The TrustedTech survey also identified an intriguing paradox within the IT and telecommunications sector. Workers in this industry feel the most confident in their ability to use AI effectively, with 87% reporting high levels of confidence. However, a significant majority (68%) within this same sector expressed concerns about shadow AI, or the unauthorized and unmanaged use of AI tools. This juxtaposition suggests that while technical proficiency may be high, the awareness and mitigation of broader AI risks, including uncontrolled proliferation, remain a challenge.

Julian Hamood, founder of TrustedTech, commented on this dichotomy: "IT and telecoms should theoretically be the industry best prepared for AI, but our data shows that confidence and readiness are two different things. You can have a workforce that knows how to use AI and still lack the guardrails for safe adoption. That gap is exactly where shadow AI lives in every industry." This observation points to a critical need for organizations to bridge the gap between AI user confidence and comprehensive AI risk management, emphasizing the importance of robust guardrails and governance structures to prevent the unchecked spread of shadow AI.

The widespread lack of adequate AI training has profound implications for organizational security, compliance, and ethical AI practices. Without proper education on potential risks, biases, and secure usage protocols, employees are more susceptible to errors, data breaches, and the inadvertent use of unapproved AI tools. This can lead to compliance violations, reputational damage, and a compromised cybersecurity posture. Addressing this training deficit is therefore paramount for fostering a culture of responsible AI adoption and ensuring that organizations can harness the benefits of AI while effectively managing its inherent risks.

The confluence of these four distinct surveys paints a comprehensive picture of the current AI landscape: rapid adoption outpacing governance, audit leaders struggling to predict emerging threats, varied ROI experiences across regions, and significant gaps in workforce AI training. Together, these findings underscore an urgent need for organizations to prioritize robust AI governance, enhance risk management capabilities, refine AI investment strategies, and invest significantly in comprehensive employee training to navigate the complex and rapidly evolving world of artificial intelligence responsibly and effectively.

By